Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1288 results
CVE-2026-63292 preview

CVE-2026-63292

GitHub0xblackash/cve-2026-63292

Documents CVE-2026-63292, a stack-based buffer overflow in Apache mod_vhost_alias, with affected versions, safe version and configuration checks, and…

configuration-auditingdefensive-toolseducation+4
16h 39m ago
CVE-2026-18143 preview

CVE-2026-18143

GitHubwayang1337/cve-2026-18143

Request a Quote for WooCommerce (Addify) <= 2.9.2 Unauthenticated arbitrary file upload via afrfq_submit_quote_via_popup

exploitationvulnerability-analysisweb-application-exploitation+2
4 days ago
CVE-2026-73570 preview

CVE-2026-73570

GitHub0xblackash/cve-2026-73570

Advisory and detection guidance for CVE-2026-73570, an unauthenticated OS command injection in Zimbra SNMP notification processing leading to remote…

defensive-toolseducationemail-security+6
12 days ago
CVE-2026-30951 preview

CVE-2026-30951

GitHubyym8538/cve-2026-30951

Proof-of-concept and vulnerable Node.js/Express/Sequelize app demonstrating CVE-2026-30951, a JSON cast-type SQL injection in Sequelize v6 where…

database-securityeducationexploitation+4
11 month ago
security-harness preview

security-harness

GitHubdmdhrumilmistry/security-harness

Multi-agent static application-security review harness for AI coding agents: maps codebases, hunts vulnerability classes, chains and verifies…

ai-securitycode-analysisdevsecops+9
225 days ago
CVE-2026-48842 preview

CVE-2026-48842

GitHub4minx/cve-2026-48842

Python PoC for CVE-2026-48842, a pre-auth SQL injection in Roundcube's virtuser_query plugin. Confirms the flaw via time-based differential and…

database-securityexploitationpenetration-testing+4
4 days ago
akca preview

akca

GitHubakha-security/akca

Evidence-oriented DAST scanner in Go that crawls web apps and APIs, then runs adaptive SQLi, XSS, RCE, SSRF, and auth checks with replayable proof.

api-security-testingdefensive-toolsdynamic-analysis-sandboxing+9
1776 days ago
CVE-2026-87915-PoC-pwnVader preview

CVE-2026-87915-PoC-pwnVader

GitHubpwnvader/cve-2026-87915-poc-pwnvader

Shell PoC for CVE-2026-87915, an unauthenticated stored XSS in the Popup Maker WordPress plugin (<=1.24.0). Fingerprints the plugin and demonstrates…

exploitationpenetration-testingvulnerability-analysis+4
10 days ago
CVE-2024-47875 preview

CVE-2024-47875

GitHubd154573r-4v3r73d/cve-2024-47875

Repository dedicated to CVE-2024-47875, providing proof-of-concept material and analysis for this specific vulnerability.

exploitationvulnerability-analysisvulnerability-scanners+1
8 days ago
CVE-2026-94545-nextjs-og-poc preview

CVE-2026-94545-nextjs-og-poc

GitHubhassham1/cve-2026-94545-nextjs-og-poc

Isolated Docker lab and non-destructive Python scanner reproducing CVE-2026-94545, the Next.js next/og ImageResponse SVG injection, with vulnerable…

exploitationlabs-practicevulnerability-analysis+3
19 days ago
CVE-2026-87902-Toolkit preview

CVE-2026-87902-Toolkit

GitHubtc4dy/cve-2026-87902-toolkit

WordPress CVE-2026-87902 LFI-to-RCE toolkit with a weaponized exploit chain (PEAR RCE, webshell, admin creation, loot) and a non-intrusive…

defensive-toolseducationexploitation+8
105 days ago
CVE-2026-87902 preview

CVE-2026-87902

GitHublutfifakee-project/cve-2026-87902

Proof-of-concept exploit for CVE-2026-87902, a WordPress Core pre-auth path traversal chaining LFI to remote code execution.

exploitationpenetration-testingremote-access-tool+3
8 days ago
CVE-2026-87902 preview

CVE-2026-87902

GitHubzer0dayf/cve-2026-87902

Python PoC script for CVE-2026-87902 that performs basic checks against a target WordPress URL with configurable page, depth, prefix, and timeout…

exploitationpenetration-testingvulnerability-analysis+3
9 days ago
CVE-2026-93485 preview

CVE-2026-93485

GitHub0xblackash/cve-2026-93485

Defensive research repository for CVE-2026-93485, a WordPress core stored XSS flaw, with version-check scanner, technical analysis, and patch…

defensive-toolseducationpapers-research+3
10 days ago
CVE-2026-18322 preview

CVE-2026-18322

GitHubi3it/cve-2026-18322

Root-cause analysis, passive version checker, and lab PoC for CVE-2026-18322, an unauthenticated privilege escalation in the Smart Popup by Supsystic…

exploitationlabs-practicepapers-research+7
1 month ago
CVE-2026-5118 preview

CVE-2026-5118

GitHubsangsenimanwartefak/cve-2026-5118

Detection tooling for CVE-2026-5118, an unauthenticated privilege escalation in Divi Form Builder <= 5.1.2, identifying affected WordPress…

defensive-toolseducationinformation-gathering+5
10 days ago
CVE-2026-91097-CVE-2026-91106 preview

CVE-2026-91097-CVE-2026-91106

GitHubnxploited/cve-2026-91097-cve-2026-91106

HPLIP < 3.26.6 — Full admin takeover via PAPPL web interface (no auth). Related to CVE-2026-91097 through CVE-2026-91106 (CVSS 9.3)

defensive-toolsexploitationinformation-gathering+7
110 days ago
Helix3-Mass-Exploiter preview

Helix3-Mass-Exploiter

GitHub6ickzone/helix3-mass-exploiter

Mass scanner and auto-write tool for CVE-2026-49049, detecting exposed Joomla Helix3 onAjaxHelix3 handlers and verifying unauthenticated file-upload…

exploitationpenetration-testingvulnerability-analysis+3
11 days ago
Previous12…72Next